January 16, 2024
The first part of this interview is a fascinating description of how John Kindervag produced the concept of Zero Trust. In the early days of networking, many users were described as “trusted users.” John questioned as to why they did not take the next step and verify then. The response was classic – because it would be rude.
Fast forward a few decades and we see countless breaches and billions of dollars of intellectual property lost because of fear of offending the sensitivities of users.
Back to 2011. Interfaces on firewalls could have varying levels of trust associated with them; the question from John Kindervag was, “why any levels at all?” His idea of zero trust resonated in the commercial and federal marketplace. For example, an Executive Order was issued in May of 2021 mandating the adoption of zero trust for the federal government.
"And we reduce it down to something small and easily known called a protect surface."
John Kindervag, Illumio Tweet
During the interview John Kindervag presents a fascinating contrast between the attack surface and the protect surface. This is a framework to allow federal leaders to prioritize what data to protect.
To gain a better understanding of how to deploy Zero Trust, The National Security Telecommunications Advisory Committee was established. It presents a five-step model and shows how to build Zero Trust one protects surface at a time.
Listen and learn about the Cloud Security Alliance and myriad ways to develop expertise in the nuances around incorporating Zero Trust into your federal network.
During the interview, John Kindervag mentioned an excellent free guide titled, “What is a Zero Trust Architecture?
If you enjoyed this episode, then you may want to listen to Ep. 115 The Role of No Code, Low Code for Federal IT

Leave a Reply